John Scott-Railton Profile picture
Sep 22, 2023 10 tweets 6 min read Read on X
🚨UPDATE your @Apple products now!

We @citizenlab w/TAG's @maddiestone caught #predator spyware attacks against a prominent pro-democracy Egyptian politician after he announced presidential ambitions.

Apple rushed a patch.

It gets crazier 1/

citizenlab.ca/2023/09/predat…
Between May and September 2023, former Egyptian MP Ahmed Eltantawy was targeted with Cytrox’s Predator spyware via links sent on SMS and WhatsApp. The targeting took place after Eltantawy publicly stated his plans to run for President in the 2024 Egyptian elections. In August and September 2023, Eltantawy’s Vodafone Egypt mobile connection was persistently selected for targeting via network injection; when Eltantawy visited certain websites not using HTTPS, a device installed at the border of Vodafone Egypt’s network automatically redirected him to a malicious website to infect his phone wi...
2/ Ahmed Eltantawy got in touch with us @citizenlab, worried his devices were targeted in #Egypt.

He was right. His iPhone on @VodafoneEgypt was targeted for network injection.

As he browsed the net, the attackers were trying to slip a #Predator infection onto his device.

Image
Image
Image
3/ It gets worse.

We attribute the spyware injection system to a @Sandvine Packet Logic product w/high confidence.

Sandvine has been accused in past of facilitating human rights abuses in the past.

Owned by NSO Group's former owner Francisco Partners.




Image
Image
Image
Image
4/ This kind of exploit delivery through injection DOES NOT require a target to click as our collaborator, the brilliant @maddiestone, points out in her post.

It's a seriously dangerous kind of attack & hard to protect against.
blog.google/threat-analysi…
Image
@maddiestone 5/ Apple moved quickly to fix the zero-day exploits @maddiestone & @billmarczak discovered.

We encourage everyone to immeidately update their apple products.

There is a piece of good security news buried in all this... Image
@maddiestone @billmarczak 6/ We believe & Apple's Security Engineering & Architecture Team confirms, Lockdown Mode would have blocked this attack!

We *strongly* encourage all Apple users that may be at risk because of who they are or what they do to enable Lockdown Mode!

support.apple.com/en-us/HT212650
Image
@maddiestone @billmarczak 7/ Ahmed ElTantawy wasn't just targeted with network injection!

He was also targeted with #Predator spyware links in decoy messages sent as texts & over @WhatsApp.

One of the attacks masqueraded as communications from the International Federation for Human Rights @fidh_en Image
@maddiestone @billmarczak @WhatsApp @fidh_en 8/ This summer the 🇺🇸US hit developer & distributor of #Predator spyware (Cytrox & Intellexa) with blacklisting.

This latest abuse revelation affirms the determination that the spyware continues to fuel human rights abuses.

By @ddimolfetta & @Post_AG
washingtonpost.com/national-secur…
Image
9/ Pulling back the lens from the tech side of this #Predator attack:

Mercenary spyware is autocrat fuel.

When you hack a pro-democracy presidential hopeful in an autocracy... you are doing dictatorship.

And spyware companies know exactly who they are selling to. Image
10/ Without brave victims like Ahmed Tantawy getting checked & coming forwards, these recent exploits would not have been found.

Billions of apple devices would still be vulnerable.

Including yours. Image

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with John Scott-Railton

John Scott-Railton Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @jsrailton

Jul 8
THE #EU parliament #spyware debate has kicked off, follow along with me.

( triggered by the hacking of a MEP investigating spyware w/Pegasus)

It kicks off as expected with Commissioner @dubravkasuica (Croatia) trying frame the issue as a national one (govs should investigate...not the parliament).

This is likely to be unpopular among MEPs concerned by spyware abuses.

Next up? MEP & spyware victim @KrzysztofBrejza 1/Image
2/ Next: MEP @KrzysztofBrejza, himself a spyware target is clear: mercenary spyware is a risk to democracy & institutions.

I've experienced it myself. Spyware is dangerous when in the hands of the wrong ppl.

A very powerful statement.Image
@krzysztofbrejza 3/ Strong statements by @alexagiussaliba: Every citizen has the right to privacy.

This issue needs to be clearly investigated.

Spyware is incredibly invasive. Image
Read 11 tweets
Jul 3
BREAKING: 🇪🇺EU lawmaker investigating spyware abuses was hacked with Pegasus.

Infected during key moments of the PEGA committee.

More proof that it's spyware open season in Europe.. yet nothing is being done 1/

Our @citizenlab forensic investigation: citizenlab.ca/research/membe…Image
Image
2/Your're a MEP on the PEGA committee.

You spend a year hearing bleak testimony from spyware victims.

Journalists..dissidents... politicians. Lives upended by hacking.

They you learn that you're also a victim.

Meet @SteliosKoul.

By @AntoanetaRoussi politico.eu/article/probe-…Image
3/ @SteliosKoul's iPhone was hacked with a Pegasus zero-click attack.

No link to click. No attachment to open.

One minute your phone is private, the next it's a spy in your pocket.

Access to all your files, camera, microphone.

Listening to meetings & your private life.Image
Read 11 tweets
Jun 8
BREAKING: NSO Group caught trying to hack across @WhatsApp. Again!

In defiance of 🇺🇸US Courts.

WhatsApp disrupted the Pegasus campaign & says it violates US Federal injunction they won against NSO.

Asks Federal judge to hold NSO Group in contempt.

Many implications... 1/Image
Image
2/ Back in 2019 @WhatsApp sued NSO Group for hacking 1.4k of their users.

NSO tried every possible tactic to dodge the case.

But lost spectacularly in 2024 and got hit with huge damages & later a permanent injunction against hacking WhatsApp.

reuters.com/technology/cyb…Image
@WhatsApp 3/ Despite bruising losses in American court...

And getting 🇺🇸US sanctioned...

NSO chose optimism & has been trying to persuade everybody that they are reformed & should be delisted

I think is the eventual goal = get Pegasus spyware into US policing.
timesofisrael.com/seeking-to-get…Image
Read 8 tweets
May 7
It is hard to denounce China's Great Firewall when European politicians are preparing to demand the same thing.

It always starts with a call to protect children.

But it ends with adults needing permission to share their political views.

Embarrassingly short sighted.
2/ Parents want to protect their children, but once you build & implement bones of a system like this, with government developed 'verification' apps you've loaded the gun & pointed it at free expression.

You also suppress innovation.
3/ The funny thing? Every dictatorial regime has struggled to fight VPNs..

So what happens? You wind up with motivated & well-resourced people circumventing your controls...

And a society where everyone simultaneously feels less private & like they should be self-censoring.
Read 5 tweets
May 2
PAY ATTENTION: China just figured out a global veto on who gets to speak.

#RightsCon is a massive tech & rights conference.

Thousands attend from everywhere.

It was scheduled for next week in #Zambia with their gov's full cooperation.

Then, 🇨🇳#China made a call. 1/Image
2/ Last Monday, the #Zambian endorsed #RightsCon. Again.

Then, pressure from #China came down hard.

Almost immediately, things went sideways.

Starting at the border...

rightscon.org/rc26-statement/Image
Image
3/ People were already flying in from all over the globe to #Zambia... thousands were to follow.

Suddenly the tone at customs changed.

Customs officials were telling exhausted & puzzled attendees that their conference was cancelled.

Meanwhile? Official silence.

Weird, right?Image
Read 8 tweets
Apr 9
BREAKING: You checked the weather this morning.

And you just told a surveillance company where you sleep.

Meet #Webloc, used by ICE, cops & foreign govs to track 500m+ phones.

No warrant required.

Our latest @citizenlab investigation + how to protect yourself 🧵/1Image
Image
2/ Heard of ADINT aka ADvertising INTelligence?

Your apps don't just show ads.

They stream of info about your GPS location + a unique identifier to HUNDREDS OF BROKERS EVERY SECOND.

The industry swears the data is "anonymous" but it's actually a Spies-eye-view. Of everyone.Image
3/ Companies peddle the BS that advertising data is 'anonymous'

They want to keep you in the dark.

Because, behind the scenes...your weather app is a blinking tracking beacon.

And then players like @penlink turn that beacon into a data flow.

And sell it to governments.
Read 15 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(